VORANT. Threat Intelligence Sign in Get the full feed

ANSSI flags RabbitMQ, Tanzu Valkey flaws

elevated vulnerability technology

ANSSI advisory lists dozens of unspecified-severity vulnerabilities in VMware/Broadcom's RabbitMQ and Tanzu for Valkey on Kubernetes, urging patching.

The French national CERT (ANSSI) issued advisory CERTFR-2026-AVI-1125 covering multiple vulnerabilities in Broadcom/VMware's open-source RabbitMQ messaging broker and Tanzu for Valkey on Kubernetes. The bulletin does not describe attack vectors, exploitability, or impact details beyond stating that the flaws could allow an attacker to trigger an unspecified security issue — the vendor has not disclosed the nature of the vulnerabilities in the referenced advisories.

Affected versions include RabbitMQ 4.0.x prior to 4.0.24, 4.1.x prior to 4.1.15, 4.2.x prior to 4.2.10, 4.3.x prior to 4.3.5, and all versions prior to 3.13.19, as well as Tanzu for Valkey on Kubernetes versions prior to 13.5.0. Over 70 CVE identifiers are referenced across six linked Broadcom security bulletins (38348–38354), spanning issue years from 2024 through 2026, suggesting this is a consolidated patch rollup rather than a single new flaw.

No indication of active exploitation, proof-of-concept availability, or threat actor involvement is provided in the advisory. Defenders running RabbitMQ or Tanzu for Valkey on Kubernetes should consult the linked Broadcom advisories for per-CVE details and apply the vendor-supplied patches to reach the fixed versions listed.

Mentioned in this report

Vulnerabilities CVE-2024-11053CVE-2024-31227CVE-2024-31228CVE-2024-31449CVE-2024-46981CVE-2024-51741CVE-2024-7264CVE-2024-9681CVE-2025-13034CVE-2025-14017CVE-2025-14524CVE-2025-15079CVE-2025-15224CVE-2025-21605CVE-2025-27151CVE-2025-32023pocCVE-2025-48367CVE-2025-6170CVE-2026-11856CVE-2026-13757CVE-2026-1965CVE-2026-33818CVE-2026-35469CVE-2026-3783CVE-2026-3784CVE-2026-39822CVE-2026-41989CVE-2026-42505CVE-2026-46600CVE-2026-4873CVE-2026-48864CVE-2026-5435CVE-2026-54369CVE-2026-54370CVE-2026-54572CVE-2026-5545CVE-2026-56853CVE-2026-56858CVE-2026-56859CVE-2026-56860

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1125

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free